Robert Biddle

dblp:50/4201 · DBLP profile ↗
← Back
75ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0001-5971-2705ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 22 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 21 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 9Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Precision Email Simulator for Research on Safety-Critical Phishing Behaviour
abstract
Email is ubiquitous, and in the context of phishing, it becomes critical, as risky behaviours like clicking on phishing links or downloading malicious files can lead to severe consequences.While much research exists on phishing susceptibility, there is still a gap in understanding factors that influence user micro-behaviour when interacting with phishing emails.To address this, we offer a tool, the Precision Email Simulator, to support phishing researchers, as well as considerations in conceptualising controlled 'experimental simulation' studies, which are currently underutilised in phishing research.The Precision Email Simulator simulates real-world email inboxes and tracks precision user data, such as time spent on messages and eye-tracking for key areas like URLs and sender addresses.We discuss the practical uses of our simulator, and provide recommendations and guidelines of using our email simulator. CCS Concepts• Security and privacy → Phishing
Sijie Zhuo, Robert Biddle, Giovanni Russello, Danielle Lottridge
CHI2
2025 Language as Lure: A Naturalistic Study on Pasifika Phishing Susceptibility
Eric Spero 0001, Isa Seow, Lucas Betts, Eddie Fuatimau, Robert Biddle, Danielle Lottridge, Giovanni Russello
SOUPS5
2025 Site Inspector: Improving Browser Communication of Website Security Information
abstract
Phishing sites exploit users’ limited understanding of website identity to mimic legitimate sites. While X.509 certificates can provide crucial cues regarding a website’s identity, current browsers fail to effectively communicate this information to users, even as phishing becomes an increasingly serious issue. To address this, we developed Site Inspector (SI), a UI tool that conveys website identity and connection encryption information, along with brief explanations of the relevant underlying security concepts. SI is implemented as a Mozilla Firefox browser extension, but the basic design could be integrated into any web browser. SI organizes content in a three-tiered abstraction hierarchy, drawing on Ecological Interface Design. The top level presents an indicator of the website owner, if known, and also whether the connection is encrypted. The second and third levels offer progressively detailed explanations of the verification process. SI adheres to design principles aimed at educating users about security through the UI while overcoming associated challenges. Its text is concise and direct, respecting limitations in users’ attentional resources and motivation to engage with security matters. As a proof of concept for SI’s principled design, we conducted a user study with 30 participants to evaluate its effectiveness in helping users differentiate real from fraudulent websites. Results suggested that SI improved users’ ability to identify fraudulent sites. Future work will involve further testing with a larger user base, integrated SI directly into browsers, and ultimately a more widespread and improved validation process for certificates, with stronger verification and transparency.
Eric Spero 0001, Robert Biddle
ACM Trans. Priv. Secur.2
2024 Reducing Workload in Using AI-based API REST Test Generation
abstract
Modern software applications, notably those utilizing microservices architectures, rely heavily on REST API technology for communication. Testing these APIs is challenging, time-consuming, and prone to errors. This paper introduces Pulse-UI, an AI-supported tool designed to enhance test sequence generation for REST APIs, aiming to reduce the workload involved in managing test sequences efficiently and improve overall test quality.
Benjamin Leu, Jonas Volken, Martin Kropp, Nejdet Dogru, Craig Anslow, Robert Biddle
AST6
2023 programmingLanguage as Language;
abstract
Programming languages are languages --- “unnatural” languages because they are constructed explicitly; “formal” languages because they rely on mathematical notations and are described mathematically; “machine” languages because they are used to communicate with machines. Above all, programming languages are “human” languages. Programs in programming languages are spoken and read and written and designed and debugged and debated by humans, supported by human communities and forming those communities in turn. Langauge implementations, being programs themselves, are likewise designed and debugged and debated by humans.
James Noble 0001, Robert Biddle
Onward!2
2023 Waste Self-reporting for Software Development Productivity Improvement
abstract
Abstract Little research has been done on enabling software development teams to self-report waste to assist in productivity improvement. This study created a waste categorization and survey for teams to identify and quantify wasteful activities. Developers from a Swiss company used the survey for three weeks. Participants found the survey helpful for identifying waste but there was little evidence that self-reported waste correlated with improved performance.
Marc Sallin, Martin Kropp, Craig Anslow, Robert Biddle
XP4
2023 SoK: Human-centered Phishing Susceptibility
abstract
Phishing is recognized as a serious threat to organizations and individuals. While there have been significant technical advances in blocking phishing attacks, end-users remain the last line of defence after phishing emails reach their email inboxes. Most of the existing literature on this subject has focused on the technical aspects related to phishing. The factors that cause humans to be susceptible to phishing attacks are still not well-understood. To fill this gap, we reviewed the available literature and systematically categorized the phishing susceptibility variables studied. We classify variables based on their temporal scope, which led us to propose a three-stage Phishing Susceptibility Model (PSM) for explaining how humans are vulnerable to phishing attacks. This model reveals several research gaps that need to be addressed to understand and improve protection against phishing susceptibility. Our review also systematizes existing studies by their sample size and generalizability and further suggests a practical impact assessment of the value of studying variables: Some more easily lead to improvements than others. We believe that this article can provide guidelines for future phishing susceptibility research to improve experiment design and the quality of findings.
Sijie Zhuo, Robert Biddle, Yun Sing Koh, Danielle Lottridge, Giovanni Russello
ACM Trans. Priv. Secur.2
2022 Understanding Leadership in Agile Software Development Teams: Who and How?
abstract
Abstract The principles in the Agile Manifesto, the Scrum Guide and most other approaches to agile software development emphasize self-organizing teams, but rarely address issues of leadership. In this paper we report on a study of the nature of different aspects of leadership in agile teams. We used an established model of leadership, distinguishing transactional and transformational styles, and asked IT professionals a set of questions about the leadership they experience, both from direct supervisors (hierarchical leadership) and from the team itself (shared leadership). We determined correlation measures of these four types of leadership with the extent of agility in the whole organization. Our results show that agility is indeed related to the transformational style, but that the transactional style also plays a part, especially as shared leadership. Furthermore, even in highly agile software development, leadership by direct supervisors still plays an important role. We propose that, as software development becomes more agile, the transactional aspects of leadership may shift away from the leadership dyad between supervisor and employee into the agile team, while transformational leadership is important for both the team and supervisors. We discuss our results in light of applications for both research and practice.
Johann C. Weichbrodt, Martin Kropp, Robert Biddle, Peggy Gregory, Craig Anslow, Ursina Maria Bühler, Magdalena Mateescu, Andreas Meier 0004
XP3
2022 What is Beautiful is Secure
abstract
Visual appeal has been shown to influence perceptions of usability and credibility, and we hypothesize that something similar is happening with user judgments of website security: What is beautiful is secure . Web certificates provide reliable information about a website’s level of security, presented in browser interfaces. Users should use this to inform their trust decisions online, but evidence from laboratory studies and real-world usage suggests that they do not. We conducted two studies—one in lab, and one online—in which participants view and interact with websites with high and low visual appeal, and various security levels, and then make security-related judgments. In both studies, participants consistently rated visually appealing websites as more secure, and indicated they would be more likely to enter sensitive information into visually appealing websites—even when they were less secure. Our results provide evidence that users rely on visual appeal when making security and trust decisions on websites. We discuss how these results may be used to help users.
Milica Stojmenovic, Eric Spero 0001, Milos Stojmenovic, Robert Biddle
ACM Trans. Priv. Secur.4
2020 We're Here to Help: Company Image Repair and User Perception of Data Breaches
abstract
Data breaches involve information being accessed by unauthorized parties. Our research concerns user perception of data breaches, especially issues relating to accountability. A preliminary study indicated many people had weak understanding of the issues, and felt they themselves were somehow responsible. We speculated that this impression might stem from organizational communication strategies. We therefore compared texts from organizations with those from external sources, such as the news media. This suggested that organizations use well-known crisis communication methods to reduce their reputational damage, and that these strategies align with repositioning of the narrative elements involved in the story. We then conducted a quantitative study, asking participants to rate either organizational texts or news texts about breaches. The findings of this study were in line with our document analysis, and suggest that organizational communication affects the users' perception of victimization, attitudes in data protection, and accountability. Our study suggests some software design and legal implications to support users protecting themselves and developing better mental models of security breaches.
Zahra Hassanzadeh, Sky Marsen, Robert Biddle
Graphics Interface3
2020 Out of Sight, Out of Mind: UI Design and the Inhibition of Mental Models of Security
abstract
In this paper we make the case that UI design inhibits mental models of security by concealing most of the security-relevant aspects of software functionality. Users are frequently required to make decisions that have important security implications, that requires a mental model of software infrastructure to know what actions are ‘safe’ versus ‘unsafe’. People build internal causal models of what they experience that have explanatory and predictive power, and therefore form the basis of the decision-making faculty. By concealing security information, user interfaces hinder the user from building the kinds of models that will keep them safer, and only the small minority who are willing to go beyond the interface will acquire this knowledge. We suggest increasing the visibility of some essential information about the security-relevant aspects of software functionality in a way that ordinary users will be able to make sense of, so that through normal interactions with software everyone develops the kind of knowledge needed to better support security. We review the cognitive science and cybersecurity literature on mental models, present three ‘case studies’ which embody the security concealment problem, and present preliminary suggestions for how UI design might amend this problem.
Eric Spero 0001, Robert Biddle
NSPW2
2020 Satisfaction and its correlates in agile software development
Martin Kropp, Andreas Meier 0004, Craig Anslow, Robert Biddle
J. Syst. Softw.4
2019 Mixed Pictures: Mental Models of Malware
abstract
Malware is a serious problem for users, who become affected as a result of the decisions they make online. This paper presents a study examining mental models related to malware and regular software, in hopes of finding clues to that will help us understand what users know about malware, and what we can do to help them make better decisions online. The study involved two drawing tasks, where participants were asked to draw their understanding of how a word processor and malware work, respectively. Several concerning patterns emerged. Participants seemed to regard malware as a fundamentally different kind of entity than regular software. They make black-and-white distinctions between malware and regular software in terms of whether the software is helpful or harmful, who the software serves, and who controls it. Finally, participants showed lesser knowledge of malware compared to regular software.
Eric Spero 0001, Milica Stojmenovic, Zahra Hassanzadeh, Sonia Chiasson, Robert Biddle
PST5
2019 Website Identity Notification: Testing the Simplest Thing That Could Possibly Work
abstract
Users are used to authenticating themselves to websites, but not for websites to authenticate to them. One readily available mechanism that may help users make safer online decisions lies in website certificates that contain website identity information. Fraudulent websites are now short-lived and present valid certificates without any identity information. Our goal was to create and test the effectiveness of simpler certificate interfaces, made to help users differentiate between identity-verified websites and those without such verification, and thus, potentially fraudulent. We conducted a study with a certificate interface prototype with simple identity notification types. Our findings suggest that presenting identity information to users can help them differentiate between real and potentially fraudulent websites. Some users were suspicious of the notifications and incorrectly felt that they could make decisions based on website appearance, so building user background knowledge is essential.
Milica Stojmenovic, Eric Spero 0001, Temitayo Oyelowo, Robert Biddle
PST4
2019 The influence of textual and verbal word-of-mouth on website usability and visual appeal
Milica Stojmenovic, Robert Biddle, John C. Grundy, Vivienne Farrell
J. Supercomput.2
2018 An exploratory study of children's online password behaviours
abstract
With increasing use of technology and the Internet among children, we explore how they create passwords to protect their personal information. We conducted a study with children 11 to 13 years to understand their password practices. The results of the study indicated that these children create simple passwords consisting of their personal information, believe that these passwords are hard for a stranger to guess and do not have good understanding of creating strong passwords.
Sumbal Maqsood, Robert Biddle, Sana Maqsood, Sonia Chiasson
IDC2
2018 Satisfaction, Practices, and Influences in Agile Software Development
abstract
The principles behind the Agile Manifesto begin with "Our highest priority is to satisfy the customer...". It also states that Agile projects should be build around motivated and self-organized teams, which might also lead to more satisfied developers. Several studies indeed report an increased job satisfaction by anecdotal evidence. In this paper we address the topic of satisfaction by in-depth analysis of the results of a nationwide survey about software development in Switzerland. We wanted to find out if satisfaction depends on the applied development method, and, more concrete, how satisfaction relates to other elements in the development process, including the use of various practices, and the influences on business, team and software issues. We found that higher satisfaction is reported more by those using Agile development than with plan-driven processes. We explored the different perspectives of developers and those with a management role and found a high consistency of satisfaction between Agile developers and Agile management, and big differences with using working plan-driven methods. We found that certain practices and influences have high correlations to satisfaction, and that collaborative processes are closely related to satisfaction, especially when combined with technical practices. Applying recursive partitioning, we found which elements were most important for satisfaction, and gained insight about how practices and influences work in combination. We also explored the relationship between satisfaction and personal experience with Agile development. Our results in this analysis are principally descriptive, but we think they can be a relevant contribution to understand the challenges for everyone involved in Agile development, and can help in the transformation to Agile.
Martin Kropp, Andreas Meier 0004, Craig Anslow, Robert Biddle
EASE4
2018 Building Website Certificate Mental Models
Milica Stojmenovic, Temitayo Oyelowo, Alisa Tkaczyk, Robert Biddle
PERSUASIVE4
2018 Hide-and-Seek with Website Identity Information
abstract
Online security involves user decision-making, so it is important to support users in this process. One important decision users face involves website identity, in order to avoid fraudulent sites. Sophisticated fraudulent sites avoid detection by using familiar names and replicated appearance, and they are active too briefly for safe browsing services to be effective. In these circumstances, website certificate identity information can help users detect fraudulent cites. In this paper we report on two studies to assess how well users are supported in this process by the Google Chrome browser. We first worked with usability evaluators and then conducted a study with real users. 70% of participants chose a fraudulent website before a 5min tutorial. After it, 100% correctly identified the proper website. With a little support, users were able to understand and apply certificate information. We suggest that a little better design, and some brief education, would benefit users.
Milica Stojmenovic, Robert Biddle
PST2
2018 Stress in Agile Software Development: Practices and Outcomes
Andreas Meier 0004, Martin Kropp, Craig Anslow, Robert Biddle
XP4
2018 The Password Life Cycle
abstract
Managing passwords is a difficult task for users, who must create, remember, and keep track of large numbers of passwords. In this work, we investigated users’ coping strategies for password management. Through a series of interviews, we identified a “life cycle” of password use and find that users’ central task in coping with their passwords is rationing their effort to best protect their important accounts. We followed up this work by interviewing experts about their password management practices and found that experts rely on the same kinds of coping strategies as non-experts, but that their increased situation awareness of security allows them to better ration their effort into protecting their accounts. Finally, we conducted a survey study to explore how the life cycle model generalizes to the larger population and find that the life cycle and rationing patterns can be seen in the broader population, but that survey respondents were less likely to characterize security management as a challenging task.
Elizabeth Stobert, Robert Biddle
ACM Trans. Priv. Secur.2
2016 Teaching Agile Collaboration Skills in the Classroom
abstract
Agile methodologies like Scrum or Extreme Programming have come a long way over the last fifteen years. Recent quantitative studies show that many companies have successfully adopted agile methodologies. It was found that in agile software development, experience leads to collaboration. It could also be shown that successful professional agile teams tend to use more collaboration practices. In 2013, the new Computer Science studies at the University of Applied Sciences were started. For this, a new curriculum was developed. This paper presents and discusses the lectures, labs and educational software projects in the programming and software engineering modules. It is discussed how agile collaboration and collaboration practices can be taught in the classroom. For this, the setup and observations of an agile student project are presented and different online collaboration tools are discussed. It is argued that software engineering education benefits significantly from embracing the modern collaboration tools the Internet has made available.
Martin Kropp, Andreas Meier 0004, Robert Biddle
CSEE&T3
2016 Agile Practices, Collaboration and Experience - An Empirical Study About the Effect of Experience in Agile Software Development
Martin Kropp, Andreas Meier 0004, Robert Biddle
PROFES3
2016 Cesar: Visual representation of source code vulnerabilities
abstract
Code analysis tools are not widely accepted by developers, and software vulnerabilities are detected by the thousands every year. We take a user-centered approach to that problem, starting with analyzing one of the popular open source static code analyzers, and uncover serious usability issues facing developers. We then design Cesar, a system offering developers a visual analysis environment to support their quest to rid their code of vulnerabilities. We present a prototype implementation of Cesar, and perform a usability analysis of the prototype and the visualizations it employs. Our analysis shows that the prototype is promising in promoting collaboration, exploration, and enabling developers to focus on the overall quality of their code as well as inspect individual vulnerabilities. We finally provide general recommendations to guide future designs of code review tools to enhance their usability.
Hala Assal, Sonia Chiasson, Robert Biddle
VizSEC3
2016 The Role of Instructional Design in Persuasion: A Comics Approach for Improving Cybersecurity
abstract
Although computer security technologies are the first line of defense to secure users, their success is dependent on individuals’ behavior. It is therefore necessary to persuade users to practice good computer security. This interview analysis of users’ conceptualization of security password guessing attacks, antivirus protection, and mobile online privacy shows that poor understanding of security threats influences users’ motivation and ability to practice safe behaviors. An online interactive comic series called Secure Comics was designed and developed based on instructional design principles to address this problem. An eye-tracking experiment suggests that the graphical and interactive components of the comics direct users’ attention and facilitate comprehension of the information. In the evaluations of Secure Comics, results from several user studies show that the comics improve understanding and motivate positive changes in security management behavior. The implication of the findings to better understand the role of instructional design and persuasion in education technology are discussed.
Leah Zhang-Kennedy, Sonia Chiasson, Robert Biddle
Int. J. Hum. Comput. Interact.3
2015 Choose Your Own Authentication
abstract
To solve the long-standing problems users have in creating and remembering text passwords, a wide variety of alternative authentication schemes have been proposed. Some of these schemes outperform others by various metrics in various contexts. However, none unilaterally outperform all others, and so text passwords persist as the main scheme applications depend upon. In this paper, we challenge the long-standing assumption that only one authentication scheme can be offered by an application service. We propose Choose Your Own Authentication (CYOA): a novel authentication architecture that enables users to choose a scheme amongst several available alternatives. CYOA would enable users to select whichever scheme best suits their preferences, abilities, and usage context. Existing text password systems could easily be replaced. Furthermore, the three-party architecture would enable delegating the management of authentication systems to trusted-third parties. The architecture allows rapid deployment and testing of novel authentication technologies. Our two-week usability study suggests that participants were willing to leverage alternative schemes. Participants were confident that CYOA could keep their financial information secure.
Alain Forget, Sonia Chiasson, Robert Biddle
NSPW3
2015 User-centred authentication feature framework
abstract
Purpose – This paper aims to propose that more useful novel schemes could develop from a more principled examination and application of promising authentication features. Text passwords persist despite several decades of evidence of their security and usability challenges. It seems extremely unlikely that a single scheme will globally replace text passwords, suggesting that a diverse ecosystem of multiple authentication schemes designed for specific environments is needed. Authentication scheme research has thus far proceeded in an unstructured manner. Design/methodology/approach – This paper presents the User-Centred Authentication Feature Framework, a conceptual framework that classifies the various features that knowledge-based authentication schemes may support. This framework can used by researchers when designing, comparing and innovating authentication schemes, as well as administrators and users, who can use the framework to identify desirable features in schemes available for selection. Findings – This paper illustrates how the framework can be used by demonstrating its applicability to several authentication schemes, and by briefly discussing the development and user testing of two framework-inspired schemes: Persuasive Text Passwords and Cued Gaze-Points. Originality/value – This framework is intended to support the increasingly diverse ecosystem of authentication schemes by providing authentication researchers, professionals and users with the increased ability to design, develop and select authentication schemes better suited for particular applications, environments and contexts.
Alain Forget, Sonia Chiasson, Robert Biddle
Inf. Comput. Secur.3
2014 SIW 2014: First Workshop on Security Information Workers
abstract
The human element is often considered the weakest element in security. Although many kinds of humans interact with systems that are designed to be secure, one particular type of human is especially important, the security information worker. Security information workers include software developers, system administrators, and intelligence analysts. This workshop aims to develop and stimulate discussion about security information workers.
Emerson R. Murphy-Hill, Heather Lipford, Bill Chu, Robert Biddle
CCS4
2014 A Password Manager that Doesn't Remember Passwords
abstract
The problems with passwords are well-known: secure passwords are difficult to remember, users have too many passwords, and users have difficulty matching their passwords to accounts. Password managers and cued graphical passwords are two password solutions that address the issues of memorability and keeping track of of passwords. We have developed Versipass, a password manager that incorporates key elements of password managers and cued graphical passwords to avoid existing problems of password memorability and associating passwords with accounts. Instead of remembering passwords, Versipass remembers image cues for graphical passwords. These cues help users to better remember their passwords and to more easily link passwords with accounts. Versipass also facilitates safe password reuse by allowing users to use the same image cue for multiple accounts.
Elizabeth Stobert, Robert Biddle
NSPW2
2014 Stop Clicking on "Update Later": Persuading Users They Need Up-to-Date Antivirus Protection
Leah Zhang-Kennedy, Sonia Chiasson, Robert Biddle
PERSUASIVE3
2014 The Password Life Cycle: User Behaviour in Managing Passwords
Elizabeth Stobert, Robert Biddle
SOUPS2
2013 Memory retrieval and graphical passwords
abstract
Graphical passwords are an alternative form of authentication that use images for login, and leverage the picture superiority effect for good usability and memorability. Categories of graphical passwords have been distinguished on the basis of different kinds of memory retrieval (recall, cued-recall, and recognition). Psychological research suggests that leveraging recognition memory should be best, but this remains an open question in the password literature. This paper examines how different kinds of memory retrieval affect the memorability and usability of random assigned graphical passwords. A series of five studies of graphical and text passwords showed that participants were able to better remember recognition-based graphical passwords, but their usability was limited by slow login times. A graphical password scheme that leveraged recognition and recall memory was most successful at combining memorability and usability.
Elizabeth Stobert, Robert Biddle
SOUPS2
2013 SourceVis: Collaborative software visualization for co-located environments
abstract
Most software development tools and applications are designed from a single-user perspective and are bound to the desktop and Integrated Development Environments (IDEs). These tools and applications make it hard for developers to analyse and interact with software artifacts collaboratively. We present SourceVisa multi-user collaborative software visualization application for use on large multi-touch tables. We describe the design and visualization features of SourceVis, present findings from a user study, and discuss the implications for building collaborative software visualization applications.
Craig Anslow, Stuart Marshall, James Noble 0001, Robert Biddle
VISSOFT4
2012 Interactional identity: designers and developers making joint work meaningful and effective
abstract
We studied collaborating interface designers and software developers engaged in multidisciplinary software creation work. Twenty-one designers and developers in 8 organizations were interviewed to understand how each specialist viewed team interactions. We also shadowed most participants as they worked on novel software projects with user interface design challenges. A grounded theory analysis of interview transcripts showed that designers and developers construct unique identities in the process of collaborating that provide meaning to their artefact-mediated interactions, and that help them to effectively accomplish the work of creating novel software. Our model of interactional identities specifies a number of aspects of joint project work in which an interactional identity is expressed. We suggest these identities are constructed to bridge a gap between how designers and developers were taught to enact their roles and the demands of project-specific work.
Judith M. Brown, Gitte Lindgaard, Robert Biddle
CSCW3
2012 Risk perception of internet-related activities
abstract
When people choose to engage in an online activity, such as doing their banking online, or making a purchase through an online merchant, they are making a trust decision about the supplier and source of the website in question. It appears that a large majority of users commonly place their trust in most, if not all, websites they encounter, and this causes significant security problems. Any solutions proposed to reduce the threat of online attacks must include a consideration of the psychological processes of the end users. This paper presents a study with the aim of understanding users' perceptions of the risks involved in engaging in online interactions. Our main findings suggest that users report higher risks associated with activities that are related to finances, such as online banking and online purchases, but attribute lower risk to online activities that are less financially-related, such as using a search engine or engaging in social networking, which are highly valued targets for attackers.
Daniel Leblanc, Robert Biddle
PST2
2012 Do you see your password?: applying recognition to textual passwords
abstract
Text-based password systems are the authentication mechanism most commonly used on computer systems. Graphical passwords have recently been proposed because the pictorial-superiority effect suggests that people have better memory for images. The most widely advocated graphical password systems are based on recognition rather than recall. This approach is favored because recognition is a more effective manner of retrieval than recall, exhibiting greater accuracy and longevity of material. However, schemes such as these combine both the use of graphical images and the use of recognition as a retrieval mechanism. This paper reports on a study that sought to address this confound by exploring the recognition of text as a novel means of authentication. We hypothesized that there would be significant differences between text recognition and text recall conditions. Our study, however, showed that the conditions were comparable; we found no significant difference in memorability. Furthermore, text recognition required more time to authenticate successfully.
Nicholas Wright, Andrew S. Patrick, Robert Biddle
SOUPS3
2012 Visual end-user security
abstract
In our work, we examine ways to apply work on graphical passwords to password management and other aspects of web security. We hope that applying knowledge from end-user computing will help to design more secure and usable systems.
Elizabeth Stobert, Robert Biddle
VL/HCC2
2012 Persuasive Cued Click-Points: Design, Implementation, and Evaluation of a Knowledge-Based Authentication Mechanism
abstract
This paper presents an integrated evaluation of the Persuasive Cued Click-Points graphical password scheme, including usability and security evaluations, and implementation considerations. An important usability goal for knowledge-based authentication systems is to support users in selecting passwords of higher security, in the sense of being from an expanded effective security space. We use persuasion to influence user choice in click-based graphical passwords, encouraging users to select more random, and hence more difficult to guess, click-points.
Sonia Chiasson, Elizabeth Stobert, Alain Forget, Robert Biddle, Paul C. van Oorschot
IEEE Trans. Dependable Secur. Comput.4
2011 Facing the facts about image type in recognition-based graphical passwords
abstract
Graphical passwords are a novel method of knowledge-based authentication that shows promise for improved usability and memorability. This paper presents two studies that examined the effect of image type in cognometric, recognition-based graphical passwords. Specifically, the usability of such authentication schemes was explored at security levels equivalent to those acceptable for text passwords. Related psychological theory was drawn upon to consider the relative strength of visual memory, to distinguish recognition from recall, and for face recognition by humans. With image type as the independent variable, login success and login time were observed as the dependent variables. Results from both studies showed that participants in the object images condition performed equal to or better than those in the face images condition. Importantly, there was no evidence to support the claim that the use of face images in the authentication scheme would result in superior user performance.
Max Hlywa, Robert Biddle, Andrew S. Patrick
ACSAC2
2011 User Study, Analysis, and Usable Security of Passwords Based on Digital Objects
abstract
Despite all efforts, password schemes intended to deploy or encourage the use of strong passwords have largely failed. As an alternative to enable users to create, maintain, and use high-quality passwords willingly, we propose Object-based Password (ObPwd), leveraging the universe of personal or personally meaningful digital content that many users now own or have access to. ObPwd converts user-selected digital objects to high-entropy text passwords. Memorization of exact passwords is replaced by remembering password objects. We present the design details, variants, and usability and security analysis of ObPwd, and report on the results of a hybrid in-lab/at-home user study on 32 participants. The results suggest the scheme has good usability, with excellent memorability, acceptable login times, and very positive user perception, achieved while providing strong security for the threat context explored. We believe this work lays the foundation for a promising password selection paradigm.
Robert Biddle, Mohammad Mannan, Paul C. van Oorschot, Tara Whalen
IEEE Trans. Inf. Forensics Secur.1
2010 Exploring usability effects of increasing security in click-based graphical passwords
abstract
Graphical passwords have been proposed to address known problems with traditional text passwords. For example, memorable user-chosen text passwords are predictable, but random system-assigned passwords are difficult to remember. We explore the usability effects of modifying system parameters to increase the security of a click-based graphical password system. Generally, usability tests for graphical passwords have used configurations resulting in password spaces smaller than that of common text passwords. Our two-part lab study compares the effects of varying the number of click-points and the image size, including when different configurations provide comparable password spaces. For comparable spaces, no usability advantage was evident between more click-points, or a larger image. This is contrary to our expectation that larger image size (with fewer click-points) might offer usability advantages over more click-points (with correspondingly smaller images). The results suggest promising opportunities for better matching graphical password system configurations to device constraints, or capabilities of individual users, without degrading usability. For example, more click-points could be used on smart-phone displays where larger image sizes are not possible.
Elizabeth Stobert, Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
ACSAC5
2010 Shoulder-surfing resistance with eye-gaze entry in cued-recall graphical passwords
abstract
We present Cued Gaze-Points (CGP) as a shoulder-surfing resistant cued-recall graphical password scheme where users gaze instead of mouse-click. This approach has several advantages over similar eye-gaze systems, including a larger password space and its cued-recall nature that can help users remember multiple distinct passwords. Our 45-participant lab study is the first evaluation of gaze-based password entry via user-selected points on images. CGP's usability is potentially acceptable, warranting further refinement and study.
Alain Forget, Sonia Chiasson, Robert Biddle
CHI3
2010 Guessing click-based graphical passwords by eye tracking
abstract
Click-based graphical passwords are a new method of authentication where passwords are created and entered by clicking in particular places on an image. This paper presents a study that investigated eye tracking as a potential threat to the security of such passwords. If the gaze data from people looking at an image resembles the click-points of other people's passwords, then covert eye tracking might be used to create dictionaries to effectively guess passwords. The study used an eye tracker to record the participants' gaze as they looked at images that had been used as the basis for passwords in an earlier study. We then compared the eye tracker data with the actual password click-points gathered during the earlier study, and conducted several forms of analysis to determine the likely success of guessing passwords. The eye tracker data did somewhat resemble the password click-points, and might offer attackers an advantage over guessing at random. The effectiveness shown for this approach was limited, however, although might allow improvement that would result in greater danger, especially if gaze data could be gathered without explicit interaction.
Daniel Leblanc, Alain Forget, Robert Biddle
PST3
2009 Multiple password interference in text passwords and click-based graphical passwords
abstract
The underlying issues relating to the usability and security of multiple passwords are largely unexplored. However, we know that people generally have difficulty remembering multiple passwords. This reduces security since users reuse the same password for different systems or reveal other passwords as they try to log in. We report on a laboratory study comparing recall of multiple text passwords with recall of multiple click-based graphical passwords. In a one-hour session (short-term), we found that participants in the graphical password condition coped significantly better than those in the text password condition. In particular, they made fewer errors when recalling their passwords, did not resort to creating passwords directly related to account names, and did not use similar passwords across multiple accounts. After two weeks, participants in the two conditions had recall success rates that were not statistically different from each other, but those with text passwords made more recall errors than participants with graphical passwords. In our study, click-based graphical passwords were significantly less susceptible to multiple password interference in the short-term, while having comparable usability to text passwords in most other respects.
Sonia Chiasson, Alain Forget, Elizabeth Stobert, Paul C. van Oorschot, Robert Biddle
CCS5
2008 Exploring User Reactions to New Browser Cues for Extended Validation Certificates
Jennifer Sobey, Robert Biddle, Paul C. van Oorschot, Andrew S. Patrick
ESORICS2
2008 Persuasion for Stronger Passwords: Motivation and Pilot Study
Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
PERSUASIVE4
2008 A Qualitative Study of Culture and Persuasion in a Smoking Cessation Game
Rilla Khaled, Ronald Fischer, James Noble 0001, Robert Biddle
PERSUASIVE4
2008 Improving text passwords through persuasion
abstract
Password restriction policies and advice on creating secure passwords have limited effects on password strength. Influencing users to create more secure passwords remains an open problem. We have developed Persuasive Text Passwords (PTP), a text password creation system which leverages Persuasive Technology principles to influence users in creating more secure passwords without sacrificing usability. After users choose a password during creation, PTP improves its security by placing randomly-chosen characters at random positions into the password. Users may shuffle to be presented with randomly-chosen and positioned characters until they find a combination they feel is memorable. In this paper, we present an 83-participant user study testing four PTP variations. Our results show that the PTP variations significantly improved the security of users' passwords. We also found that those participants who had a high number of random characters placed into their passwords would deliberately choose weaker pre-improvement passwords to compensate for the memory load. As a consequence of this compensatory behaviour, there was a limit to the gain in password security achieved by PTP.
Alain Forget, Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
SOUPS4
2008 Culture and Agile: Challenges and Synergies
Steven Fraser 0001, Pekka Abrahamsson, Robert Biddle, Jutta Eckstein, Philippe Kruchten, Dennis Mancl, Werner Wild
XP3
2008 Experience on the Human Side of Agile
Angela Martin, James Noble 0001, Robert Biddle
XP3
2007 Graphical Password Authentication Using Cued Click Points
Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
ESORICS3
2007 Fine Tuning the Persuasion in Persuasive Games
Rilla Khaled, Pippin Barr, James Noble 0001, Ronald Fischer, Robert Biddle
PERSUASIVE5
2007 A second look at the usability of click-based graphical passwords
abstract
Click-based graphical passwords, which involve clicking a set of user-selected points, have been proposed as a usable alternative to text passwords. We conducted two user studies: an initial lab study to revisit these usability claims, explore for the first time the impact on usability of a wide-range of images, and gather information about the points selected by users; and a large-scale field study to examine how click-based graphical passwords work in practice. No such prior field studies have been reported in the literature. We found significant differences in the usability results of the two studies, providing empirical evidence that relying solely on lab studies for security interfaces can be problematic. We also present a first look at whether interference from having multiple graphical passwords affects usability and whether more memorable passwords are necessarily weaker in terms of security.
Sonia Chiasson, Robert Biddle, Paul C. van Oorschot
SOUPS2
2007 Helping users create better passwords: is this the right approach?
abstract
Users tend to form their own mental models of good passwords regardless of any instructions provided. They also tend to favour memorability over security. In our study comparing two mnemonic phrase-based password schemes, we found a surprising number of participants misused both schemes. Intentional or not, they misused the system such that their task of password creation and memorization became easier. Thus, we believe that instead of better instructions or password schemes, a new approach is required to convince users to create more secure passwords. One possibility may lie in employing Persuasive Technology.
Alain Forget, Sonia Chiasson, Robert Biddle
SOUPS3
2007 Up-Front Interaction Design in Agile Development
Jennifer Ferreira, James Noble 0001, Robert Biddle
XP3
2007 Motivation and Cohesion in Agile Teams
Elizabeth Whitworth, Robert Biddle
XP2
2007 Video game values: Human-computer interaction and games
abstract
Current human–computer interaction (HCI) research into video games rarely considers how they are different from other forms of software. This leads to research that, while useful concerning standard issues of interface design, does not address the nature of video games as games specifically. Unlike most software, video games are not made to support external, user-defined tasks, but instead define their own activities for players to engage in. We argue that video games contain systems of values which players perceive and adopt, and which shape the play of the game. A focus on video game values promotes a holistic view of video games as software, media, and as games specifically, which leads to a genuine video game HCI.
Pippin Barr, James Noble 0001, Robert Biddle
Interact. Comput.3
2006 Generic ownership for generic Java
abstract
Ownership types enforce encapsulation in object-oriented programs by ensuring that objects cannot be leaked beyond object(s) that own them. Existing ownership programming languages either do not support parametric polymorphism (type genericity) or attempt to add it on top of ownership restrictions. Generic Ownership provides per-object ownership on top of a sound generic imperative language. The resulting system not only provides ownership guarantees comparable to established systems, but also requires few additional language mechanisms due to full reuse of parametric polymorphism. We formalise the core of Generic Ownership, highlighting that only restriction of this calls and owner subtype preservation are required to achieve deep ownership. Finally we describe how Ownership Generic Java (OGJ) was implemented as a minimal extension to Generic Java in the hope of bringing ownership types into mainstream programming.
Alex Potanin, James Noble 0001, Dave Clarke 0001, Robert Biddle
OOPSLA4
2006 Feeling Strangely Fine: The Well-Being Economy in Popular Games
Pippin Barr, Rilla Khaled, James Noble 0001, Robert Biddle
PERSUASIVE4
2006 Well-Being to "Well Done!": The Development Cycle in Role-Playing Games
Pippin Barr, Rilla Khaled, James Noble 0001, Robert Biddle
PERSUASIVE4
2006 Investigating Social Software as Persuasive Technology
Rilla Khaled, Pippin Barr, James Noble 0001, Robert Biddle
PERSUASIVE4
2006 Our Place or Mine? Exploration into Collectivism-Focused Persuasive Technology Design
Rilla Khaled, Pippin Barr, James Noble 0001, Ronald Fischer, Robert Biddle
PERSUASIVE5
2006 A Usability Study and Critique of Two Password Managers
Sonia Chiasson, Paul C. van Oorschot, Robert Biddle
USENIX Security Symposium3
2006 Featherweight generic confinement
abstract
Existing approaches to object encapsulation either rely on ad hoc syntactic restrictions or require the use of specialised type systems. Syntactic restrictions are difficult to scale and to prove correct, while specialised type systems require extensive changes to programming languages. We demonstrate that confinement can be enforced cheaply in Featherweight Generic Java, with no essential change to the underlying language or type system. This result demonstrates that polymorphic type parameters can simultaneously act as ownership parameters and should facilitate the adoption of confinement and ownership type systems in general-purpose programming languages.
Alex Potanin, James Noble 0001, Dave Clarke 0001, Robert Biddle
J. Funct. Program.4
2004 When XP Met Outsourcing
Angela Martin, Robert Biddle, James Noble 0001
XP2
2004 Checking ownership and confinement
abstract
Abstract A number of proposals to manage aliasing in Java‐like programming languages have been advanced over the last five years. It is not clear how practical these proposals are, that is, how well they relate to the kinds of programs currently written in Java‐like languages. To address this problem, we analysed heap snapshots from a corpus of Java programs. Our results indicate that object‐oriented programs do in fact exhibit symptoms of encapsulation in practice, and that proposed models of uniqueness, ownership, and confinement can usefully describe the aliasing structures of object‐oriented programs. Understanding the kinds of aliasing present in programs should help us to design formalisms to make explicit the kinds of aliasing implicit in object‐oriented programs. Copyright © 2004 John Wiley & Sons, Ltd.
Alex Potanin, James Noble 0001, Robert Biddle
Concurr. Pract. Exp.3
2003 Being Jane Malkovich: A Look Into the World of an XP Customer
Angela Martin, James Noble 0001, Robert Biddle
XP3
2002 Patterns as Signs
James Noble 0001, Robert Biddle
ECOOP2
2002 Supporting Reusable Use Cases
Robert Biddle, James Noble 0001, Ewan D. Tempero
ICSR1
2000 Simulating multiple inheritance in Java
Ewan D. Tempero, Robert Biddle
J. Syst. Softw.2
1998 The retention of women in the computing sciences (panel)
abstract
The recruiting and retention of women in the computing sciences has been an area of study for many years. In 1992, 49% of all high school graduates were women prepared and interested in the computer science and engineering disciplines. Of the bachelor of science degrees awarded, only 31% went to women in these fields of study. Women represented only 28% of the master's degrees and 11% of the Ph.D.s awarded during that time. The following year, 1993, reported a drop of women earning B.S. degrees to 28%, with 27% and 14% of master's and Ph.Ds degrees awarded, respectively, to women.A panel of six discuss why women who are initially attracted to computer science bail out without completing degree requirements, most in the first two years of undergraduate study. The panelists present diverse positions as to why fewer women persevere and experimental efforts for increasing the retention rate among women. The action plans developed from the investigations include curriculum changes and support group activities. The panelists share feedback from surveys, program modifications, support group activities and personal experiences to provide a comprehensive view of the problem and possible solutions applicable to a wide range of environments. The panelists' positions follow.
Sharon N. Vest, Robert Biddle, Christina Björkman, Linda M. Null, Eric Roberts 0001, Greg W. Scragg
SIGCSE2
1998 Teaching programming by teaching principles of reusability
Robert Biddle, Ewan D. Tempero
Inf. Softw. Technol.1
1997 Women in introductory computer science: experience at Victoria University of Wellington
abstract
This paper documents efforts that the department has made to support women students between 1991 and the 1996. Our major goal has been to reduce the high withdrawal rate of women students in our entry level course in computer science. We describe the approaches that have been taken to address this concern, and present the data which has been collected to track the results of our efforts. Our data suggests that providing a gender neutral content is not enough to ensure that men and women will retain similarly. In this paper we suggest policies which we feel may be beneficial in achieving similar male and female retention rates.
Judy Brown, Peter Andreae, Robert Biddle, Ewan D. Tempero
SIGCSE3
1996 Understanding the impact of language features on reusability
abstract
We present a conceptual model for helping us understand the nature of software reusability, particularly to help us understand how language features affect the reusability of software. The fundamental concept for our model is that of dependencies. We identify properties of dependencies between segments of code that are important to reusability. We validate our model by showing its application to well understood principles of reusability. We demonstrate that being able to describe these principles in a single framework allows us to gain a better understanding of reusability.
Robert Biddle, Ewan D. Tempero
ICSR1
1996 Explaining inheritance: a code reusability perspective
abstract
Programmers new to the object-oriented paradigm often have difficulty learning how to use inheritance properly. In this paper we introduce an approach to explaining inheritance that is based on understanding the nature of reusability. We show how the important aspect of inheritance is interface conformance, and explain the role this plays in supporting reusability. We then outline a method for determining when and how to use both single inheritance and multiple inheritance, and discuss the implications of our approach.
Robert Biddle, Ewan D. Tempero
SIGCSE1